alert-investigation

Điều tra một cảnh báo quan sát được kích hoạt và trả về chẩn đoán có cấu trúc với nguyên nhân có khả năng, phạm vi và các bước tiếp theo.

npx skills add https://github.com/launchdarkly/ai-tooling --skill alert-investigation

Alert investigation

You are investigating a specific triggered alert. Alerts arrive with structured context — an alert ID, name, threshold, value that crossed it, and a time range. Your job is to explain why it fired, assess scope, and recommend action.

Prerequisites

This skill uses the following LaunchDarkly observability MCP tools:

  • query-logs — query log records
  • query-traces — query distributed traces
  • query-error-groups — query error groups
  • query-sessions — query sessions
  • query-aggregations — query aggregated/time-bucketed metrics
  • get-keys — discover available attribute keys before filtering

Workflow

  1. Parse the alert context. The first turn of the conversation carries alert variables: alertID, alertName, alertValue, group, groupValue, query, thresholdWindow, timeRange, plus a product-specific link. Use these, don't re-derive them.
  2. Load the per-product companion. Based on the alert's product type, load the matching companion: logs.md, traces.md, errors.md, sessions.md, or metrics.md. Each captures the per-product investigation shape.
  3. Run the investigation using the methodology from the investigate skill (cross-reference logs/traces/errors/sessions/metrics; cite identifiers; aggregate before paginating). Scoped to the alert's time range and filter.
  4. Produce a structured diagnosis. See output template below.

Output template

Alert investigations have a consistent structure so consumers (notification channels, dashboards) can parse them.

## What triggered

<1-2 sentences naming the alert, the threshold, and the value that crossed it.>

## Likely cause

<Root-cause narrative citing specific evidence: trace IDs, log timestamps, error group IDs, flag keys, deploy timing.>

## Scope

<Who or what is affected. Number of users, services, sessions, error groups. Time window of impact.>

## Next steps

<1-3 concrete actions the on-call or owner should take. Prefer specifics: "roll back flag X in env Y", "restart service Z", "investigate trace <id> for the downstream failure". Avoid "investigate further" — if you don't have a root cause, say what specifically should be investigated and how.>

When to load which companion

  • logs.md — log alert, log pattern alert
  • traces.md — latency alert, trace-error-rate alert, span-specific alert
  • errors.md — error-rate alert, new-error-group alert, crash-rate alert
  • sessions.md — session-health alert, user-facing-error-rate alert
  • metrics.md — custom metric threshold, aggregated metric alert, composite alert

If the alert crosses product boundaries (e.g. a metric alert driven by error data), load both companions.

Guidelines

  • Stay tight. Alert investigations feed notifications — keep the output structured and scannable. No preamble ("Here is my analysis..."), no repeated framing.
  • Cite identifiers. Every claim in the diagnosis should reference a specific trace ID, error group ID, session ID, or log timestamp.
  • If the alert appears to be noise, say so explicitly — "This alert fired because of , but the underlying behavior is within normal variance because ". Noise is a legitimate outcome; don't invent root causes.
  • Don't redo the investigation you just did. The diagnosis output should let the on-call act without re-querying.

Thêm skills từ launchdarkly

aiconfig-online-evals
launchdarkly
KHÔNG DÙNG NỮA chuyển hướng — kỹ năng này đã được đổi tên thành online-evals. Không sử dụng kỹ năng này; hãy gọi online-evals thay thế. Chỉ giữ lại để các tham chiếu cũ đến…
official
launchdarkly-experiment-setup
launchdarkly
Thiết lập và chạy các thử nghiệm trong LaunchDarkly. Tạo thử nghiệm với các chỉ số, phương pháp xử lý và cấu hình flag, bắt đầu các vòng lặp để thu thập dữ liệu, hoán đổi thiết kế giữa…
official
custom-metrics
launchdarkly
Tạo, theo dõi, truy xuất, cập nhật và xóa các chỉ số kinh doanh tùy chỉnh cho cấu hình. Bao gồm toàn bộ vòng đời: xác định loại chỉ số qua API, phát sự kiện qua SDK, và…
official
projects
launchdarkly
Hướng dẫn thiết lập các dự án LaunchDarkly trong codebase của bạn. Giúp bạn đánh giá stack, chọn cách tiếp cận phù hợp và tích hợp quản lý dự án mà…
official
aiconfig-ai-metrics
launchdarkly
ĐÃ LỖI THỜI chuyển hướng — kỹ năng này đã được đổi tên thành built-in-metrics. Không sử dụng kỹ năng này; hãy gọi built-in-metrics thay thế. Chỉ giữ lại để các tham chiếu cũ đến…
official
aiconfig-projects
launchdarkly
ĐÃ LỖI THỜI chuyển hướng — kỹ năng này đã được đổi tên thành projects. Không sử dụng kỹ năng này; hãy gọi projects thay thế. Chỉ giữ lại để các tham chiếu cũ đến aiconfig-projects…
official
aiconfig-migrate
launchdarkly
ĐÃ LỖI THỜI chuyển hướng — kỹ năng này đã được đổi tên thành migrate. Không sử dụng kỹ năng này; hãy gọi migrate thay thế. Chỉ giữ lại để các tham chiếu cũ đến aiconfig-migrate vẫn…
official
aiconfig-tools
launchdarkly
ĐÃ LỖI THỜI chuyển hướng — kỹ năng này đã được đổi tên thành tools. Không sử dụng kỹ năng này; hãy gọi tools thay thế. Chỉ giữ lại để các tham chiếu cũ đến aiconfig-tools vẫn hoạt động…
official